npm altweb-contextstdioAGPL-3.0updated 15d ago
Signed context capsules for AI agents — Markdown compiled into self-contained, verifiable, optionally encrypted artifacts + an MCP loader that refuses unsigned or untrusted context. Verify before you inject.
What can you do with ALTWEB Context Loader?
ALTWEB — signed context capsules
Signed context capsules for AI agents — Markdown compiled into self-contained, verifiable, optionally encrypted artifacts + an MCP loader that refuses unsigned or untrusted context. Verify before you inject.
AI agents run on plain-text context: instructions, personas, skills, memory files. None of it has provenance — anything that can write those files can poison them. ALTWEB gives context a chain of custody, and makes the loader refuse anything that lacks one:
- Capsule — markdown compiled into a single
.altweb.htmlfile (or URL): content compressed (deflate), optionally encrypted (AES-256-GCM), optionally signed (ECDSA P-256). Self-contained — opens in any browser, verifies offline, needs no server: you hand someone a file, not a database. - Verified context loading — the
altweb-contextMCP server loads a capsule into your agent only when the signature is valid and the signer's public key is in your trust file. Unsigned, tampered, or untrusted capsules are refused at load time, with an explicit reason. Refusal is the default: an empty trust file rejects everything, signed or not.
you write MD ──► altweb compile --sign ──► capsule (.altweb.html / URL)
│
agent asks for context ──► altweb-context ──► verify signature + trust
│
trusted ──► markdown injected
everything else ──► REFUSED (reason)
Packages
| Package | What it is |
|---|---|
altweb |
CLI: altweb compile / decode / verify / keygen (packages/cli) |
altweb-context |
MCP server: load_capsule, verify_capsule, list_trusted_keys (packages/mcp) |
@altweb/core |
Headless engine: content model, codec, crypto, markdown, sanitize (bundled into both; npm release planned) |
@altweb/editor |
Notion-style editor (built on Novel) with one-click capsule export |
site/ |
Documentation site (Astro + Starlight) |
Quickstart
Both tools are on npm — nothing to clone:
# create your signing identity (deterministic from a passphrase; only the
# public key + fingerprint are stored, in ~/.altweb/identity.json)
npx altweb keygen --save
# write, compile, sign
echo "# My agent's operating notes" > notes.md
npx altweb compile notes.md -o notes.altweb.html --sign
# verify anywhere, offline
npx altweb verify notes.altweb.html
Wire the loader into an MCP client (Claude Code example):
claude mcp add altweb-context -- npx -y altweb-context
(From source: npm install && npm run build, then use the bundles under
packages/*/dist/.)
Trust a signer by adding its full public key to ~/.altweb/trusted-keys.json
(the UNTRUSTED_KEY refusal message hands you the ready-made entry; the short
fingerprint is a human label, not the trust anchor):
{ "keys": [ { "name": "Me", "publicKey": "<base64url SPKI>", "fingerprint": "ab:12:..." } ] }
What a signature proves — and what it does not
A valid signature proves who authored the capsule and that the bytes are intact. It does not make the content safe or true. The trust file is your policy; keep it short.
Pick a long passphrase. Identities derive deterministically from your passphrase via Argon2id with a fixed protocol salt (that is what makes them portable with nothing stored). Memory-hardness makes mass dictionary attacks economically hostile, but the passphrase's entropy is still the identity's foundation. Use a 16+ character diceware-style phrase; the tooling enforces a minimum strength.
Security
Content is sanitized with DOMPurify on decode; artifacts carry a CSP; the
codec validates structure with zod. See site/ docs → Security model for the
full write-up, including the encrypted-capsule caveat (the signature covers
the decrypted payload, so verification completes after decryption).
Roadmap
Near-term, in rough order:
@altweb/coreon npm — the engine as an installable library, for programmatic use (the CLI and loader already ship it bundled).- Hardware-backed identity (FIDO2 / passkeys) — an optional identity type alongside the passphrase one: the private key lives in a security key or secure enclave, never extractable, signing requires physical presence. The passphrase identity stays the default — "a passphrase is a keypair" — hardware keys add something you have for those who want it.
Credits
Built on excellent open source: Novel (Apache-2.0) and Tiptap (MIT) for the editor; DOMPurify, marked, pako, zod, @noble/curves in the engine. See NOTICE.
License
ALTWEB is dual-licensed:
- Open source: AGPL-3.0-or-later. Free to use, study, modify,
and share — with one core obligation: if you modify ALTWEB and distribute it
or run it as a network service (e.g. hosting
altweb-contextfor others), you must release your modified source under the AGPL. - Commercial: by agreement. To use ALTWEB in a closed-source product, or as a hosted service without publishing your changes, you need a separate commercial license. See COMMERCIAL.md.
Copyright © 2026 Daniel C. ȘOIMU. Bundled third-party components keep their own (permissive) licenses — see NOTICE.
Install
Add ALTWEB Context Loader to your client. Pick the one you use.
claude mcp add altweb-context -- npx -y altweb-contextcodex mcp add altweb-context -- npx -y altweb-contextamp mcp add altweb-context -- npx -y altweb-context{
"mcpServers": {
"altweb-context": {
"command": "npx",
"args": [
"-y",
"altweb-context"
]
}
}
}Add to `claude_desktop_config.json`, then restart Claude Desktop.
{
"mcpServers": {
"altweb-context": {
"command": "npx",
"args": [
"-y",
"altweb-context"
]
}
}
}Add to `~/.cursor/mcp.json`, or `.cursor/mcp.json` for a single project.
code --add-mcp '{"name":"altweb-context","command":"npx","args":["-y","altweb-context"]}'Or add the block manually to `.vscode/mcp.json` under `servers`.
{
"mcpServers": {
"altweb-context": {
"command": "npx",
"args": [
"-y",
"altweb-context"
]
}
}
}Add to `~/.codeium/windsurf/mcp_config.json`.
{
"mcpServers": {
"altweb-context": {
"command": "npx",
"args": [
"-y",
"altweb-context"
]
}
}
}Add to `cline_mcp_settings.json` via the MCP Servers panel.
{
"mcpServers": {
"altweb-context": {
"command": "npx",
"args": [
"-y",
"altweb-context"
]
}
}
}Add to `~/.gemini/settings.json`.
{
"mcpServers": {
"altweb-context": {
"type": "local",
"command": "npx",
"args": [
"-y",
"altweb-context"
],
"tools": [
"*"
]
}
}
}Add to `~/.copilot/mcp-config.json`, or run `/mcp add` inside the CLI.
{
"context_servers": {
"altweb-context": {
"command": {
"path": "npx",
"args": [
"-y",
"altweb-context"
]
}
}
}
}Add to your Zed `settings.json`.
npx -y altweb-contextRun `goose configure`, choose **Add Extension → Command-line Extension**, and paste this command.
Score
39 / 100
Incomplete
- Documentation20/25
- Maintenance19/25
- Trust13/20
- Capability0/15
- Install experience12/15
- Documents what it does and how to connect
- Has a resolvable package or endpoint
- Exposes at least one tool, prompt or resource
- README has substantive content
- Includes a code example
- Documents its configuration
- Mentions credentials or security posture
- Last commit 8 days ago
- Has a release history
- Repository is not archived
- Licensed AGPL-3.0
- Namespace verified in the official MCP registry
- Claimed by its owner
- Published under an organisation
- 0 tool(s) documented
- Provides prompt templates
- Provides resources
- 12 documented install method(s)
- Published to a package registry
- Offers a hosted endpoint — no local install
Version history
| Versions | Published |
|---|---|
| 1.1.0Latest | Aug 22, 2026 |
| 1.0.2 | Aug 21, 2026 |